Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SysVert' = '%HOMEPATH%\AppData\Local\SysVert\sysvert.vbs'
- '<SYSTEM32>\wscript.exe' "%TEMP%\1.tmp\sysvert.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\run.cmd" "
- %TEMP%\1.tmp\sysvert.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\myip.dnsomatic[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\sendmessage[1]
- %TEMP%\1.tmp\run.cmd
- %TEMP%\1.tmp\cpu.zip
- %TEMP%\1.tmp\radeon.zip
- 'cr##t4u.com':80
- 'my##.#nsomatic.com':80
- 'localhost':1036
- cr##t4u.com/index.php/site/sendmessage?us################################################################################################################################
- my##.#nsomatic.com/
- DNS ASK cr##t4u.com
- DNS ASK my##.#nsomatic.com
- ClassName: 'Indicator' WindowName: '(null)'